Security
Security and responsible disclosure
We take security seriously. If you find a vulnerability, we appreciate responsible disclosure so we can investigate and fix issues quickly.
Report a vulnerability
Email security@sightwhale.com with a clear description, reproduction steps, and impact assessment. If possible, include:
- Affected URL(s) and request/response samples (redact secrets)
- Steps to reproduce and expected vs. actual behavior
- Proof of concept (PoC) with minimal risk
- Suggested remediation, if you have one
Safe harbor
We welcome good-faith security research. Please avoid actions that could harm users or the platform, such as data exfiltration, service disruption, or social engineering.
Scope
- In scope: sightwhale.com and official subdomains/services
- Out of scope: third-party services not controlled by Sight Whale
What we do
- We triage reports and respond as quickly as practical
- We prioritize fixes by severity and exploitability
- We may request additional details to validate impact
User data
Never send us secrets (API keys, passwords, private keys). If you believe you have found exposed data, stop and contact us immediately.